MailPoet – Newsletters, Email Marketing, and Automation <= 5.40.0 - Unauthenticated Authentication Bypass via Brute-Forceable Subscriber Link Tokens
- ID
- WPSEC-2026-0499
- Plugin
- MailPoet – Newsletters, Email Marketing, and Automation (mailpoet)
- Affected
- all versions before 5.41.0
- Remediation
- Update to 5.41.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-330
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- MailPoet – Newsletters, Email Marketing, and Automation on WPSec AttackSurface
- Fix released
- Published
Description
The MailPoet plugin for WordPress is vulnerable to Authentication Bypass via subscriber link tokens in all versions up to, and including, 5.40.0. This is due to subscribers that are not given a random token when created, such as those added by the WordPress Users and WooCommerce Customers list synchronization, receiving a token of only six hexadecimal characters derived from the site's AUTH_KEY and the subscriber's email address, leaving roughly 16.7 million possible values. This makes it possible for unauthenticated attackers who know such a subscriber's email address to brute-force the token against the public subscription pages and then view and change that subscriber's subscription details and list memberships, unsubscribe them, or confirm a pending subscription on their behalf.
References
- https://wpsec.com/vuln/WPSEC-2026-0499/
- https://plugins.svn.wordpress.org/mailpoet/tags/5.41.0/
- https://wordpress.org/plugins/mailpoet/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS